Download CAS-004 Exam Dumps Questions to get 100% Success in CompTIA [Q38-Q59]

Share

Download CAS-004 Exam Dumps Questions to get 100% Success in CompTIA 

100% Accurate Answers! CAS-004 Actual Real Exam Questions

NEW QUESTION # 38
Company A acquired Company B.
During an audit, a security engineer found Company B's environment was inadequately patched.
In response, Company A placed a firewall between the two environments until Company B's infrastructure could be integrated into Company A's security program.
Which of the following risk-handling techniques was used?

  • A. Accept
  • B. Avoid
  • C. Transfer
  • D. Mitigate

Answer: D


NEW QUESTION # 39
A security analyst notices a number of SIEM events that show the following activity:

Which of the following response actions should the analyst take FIRST?

  • A. Disable powershell.exe on all Microsoft Windows endpoints.
  • B. Disable local administrator privileges on the endpoints.
  • C. Configure the forward proxy to block 40.90.23.154.
  • D. Restart Microsoft Windows Defender.

Answer: C

Explanation:
Stop the data exfiltration and sever all malicious traffic first, and then clean up the internal mess.


NEW QUESTION # 40
A customer reports being unable to connect to a website at www.test.com to consume services. The customer notices the web application has the following published cipher suite:

Which of the following is the MOST likely cause of the customer's inability to connect?

  • A. The server name should be test.com.
  • B. Weak ciphers are being used.
  • C. The public key should be using ECDSA.
  • D. The default should be on port 80.

Answer: B

Explanation:
Reference:
https://security.stackexchange.com/questions/23383/ssh-key-type-rsa-dsa-ecdsa-are-there-easy-answers-for-whic


NEW QUESTION # 41
A vulnerability analyst identified a zero-day vulnerability in a company's internally developed software. Since the current vulnerability management system does not have any checks for this vulnerability, an engineer has been asked to create one. Which of the following would be BEST suited to meet these requirements?

  • A. OVAL
  • B. ARF
  • C. ISACs
  • D. Node.js

Answer: A


NEW QUESTION # 42
A forensic expert working on a fraud investigation for a US-based company collected a few disk images as evidence.
Which of the following offers an authoritative decision about whether the evidence was obtained legally?

  • A. Police
  • B. Lawyers
  • C. Upper management team
  • D. Court

Answer: B


NEW QUESTION # 43
During a remodel, a company's computer equipment was moved to a secure storage room with cameras positioned on both sides of the door. The door is locked using a card reader issued by the security team, and only the security team and department managers have access to the room. The company wants to be able to identify any unauthorized individuals who enter the storage room by following an authorized employee.
Which of the following processes would BEST satisfy this requirement?

  • A. Require both security and management to open the door.
  • B. Monitor camera footage corresponding to a valid access request.
  • C. Issue new entry badges on a weekly basis.
  • D. Require department managers to review denied-access requests.

Answer: A


NEW QUESTION # 44
A security consultant needs to protect a network of electrical relays that are used for monitoring and controlling the energy used in a manufacturing facility.
Which of the following systems should the consultant review before making a recommendation?

  • A. FPGA
  • B. CAN
  • C. ASIC
  • D. SCADA

Answer: D

Explanation:
The other systems listed (CAN, ASIC, and FPGA) are not directly related to the protection of electrical relays in a manufacturing facility. CAN (Controller Area Network) is a communication protocol used in automobiles and other vehicles to allow different electronic systems to communicate with each other. ASIC (Application Specific Integrated Circuit) and FPGA (Field- Programmable Gate Array) are types of computer chips that are used in a wide range of applications, including industrial control systems.


NEW QUESTION # 45
A security architect is implementing a web application that uses a database back end. Prior to the production, the architect is concerned about the possibility of XSS attacks and wants to identify security controls that could be put in place to prevent these attacks. Which of the following sources could the architect consult to address this security concern?

  • A. SDLC
  • B. OWASP
  • C. IEEE
  • D. OVAL

Answer: B

Explanation:
The architect can consult OWASP resources, such as the OWASP Top Ten and the OWASP XSS Prevention Cheat Sheet, to identify best practices and recommendations for preventing XSS attacks in the web application.


NEW QUESTION # 46
A company is deploying a DIP solution and scanning workstations and network drives for documents that contain potential Pll and payment card data. The results of the first scan are as follows:

The security learn is unable to identify the data owners for the specific files in a timely manner and does not suspect malicious activity with any of the detected files.
Which of the following would address the inherent risk until the data owners can be formally identified?

  • A. Move the files from the marketing share to a secured drive.
  • B. Search the metadata for each file to locate the file's creator and transfer the files to the personal drive of the listed creator.
  • C. Configure the DLP tool to delete the files on the shared drives
  • D. Remove the access for the internal audit group from the accounts payable and payroll shares

Answer: A


NEW QUESTION # 47
SIMULATION
You are about to enter the virtual environment.
Once you have completed the item in the virtual environment, you will NOT be allowed to return to this item.
Click Next to continue.

Question and Instructions
DO NOT perform the following actions within the virtual environment. Making any of these changes will cause the virtual environment to fail and prevent proper scoring.
1. Disabling ssh
2. Disabling systemd
3. Altering the network adapter 172.162.0.0
4. Changing the password in the lab admin account
Once you have completed the item in the virtual environment. you will NOT be allowed to return to this item.
TEST QUESTION
This system was recently patched following the exploitation of a vulnerability by an attacker to enable data exfiltration.
Despite the vulnerability being patched, it is likely that a malicious TCP service is still running and the adversary has achieved persistence by creating a systemd service.
Examples of commands to use:
kill, killall
lsof
man, --help (use for assistance)
netstat (useful flags: a, n, g, u)
ps (useful flag: a)
systemctl (to control systemd)
Please note: the list of commands shown above is not exhaustive. All native commands are available.
INSTRUSTIONS
Using the following credentials:
Username: labXXXadmin
Password: XXXyyYzz!
Investigate to identify indicators of compromise and then remediate them. You will need to make at least two changes:
1. End the compromised process that is using a malicious TCP service.
2. Remove the malicious persistence agent by disabling the service's ability to start on boot.

Answer:

Explanation:
Use sudo before any command the password is the same password provided, everything in <> is not part of the command is variable. Sudo will show you every detail you need. First command
$sudo netstat -nltp, this will show you ip, port, pid, name of task.
For added value you can also run $sudo lsof -i :<port>. Now you need to find the service so you use $sudo systemctl --type=service | grep <name of task>, this will give you <something>.service my was <something>-resolve.service forgot the full name.
Suggest you do a $sudo systemctl status <full name service> to compare. After all that lets kill it all, First kill the pid $sudo kill -9 <pid>. Then lets complete the second part $sudo systemctl stop
<full name service>, follow by $sudo systemctl disable <full name service>.
Now for the cream on the top you verify that is gone $sudo netstat -nltp and $sudo systemctl status <full name service>.


NEW QUESTION # 48
Given the following log snippet from a web server:

Which of the following BEST describes this type of attack?

  • A. Cross-site scripting
  • B. SQL injection
  • C. Brute-force
  • D. Cross-site request forgery

Answer: B


NEW QUESTION # 49
A bank is working with a security architect to find the BEST solution to detect database management system compromises. The solution should meet the following requirements:
* Work at the application layer
* Send alerts on attacks from both privileged and malicious users
* Have a very low false positive
Which of the following should the architect recommend?

  • A. WAF
  • B. UTM
  • C. DAM
  • D. FIM
  • E. NIPS

Answer: C


NEW QUESTION # 50
A security analyst notices a number of SIEM events that show the following activity:

Which of the following response actions should the analyst take FIRST?

  • A. Disable powershell.exe on all Microsoft Windows endpoints.
  • B. Disable local administrator privileges on the endpoints.
  • C. Configure the forward proxy to block 40.90.23.154.
  • D. Restart Microsoft Windows Defender.

Answer: C

Explanation:
Explanation
top the data exfiltration and sever all malicious traffic first, and then clean up the internal mess.


NEW QUESTION # 51
A security analyst is reading the results of a successful exploit that was recently conducted by third-party penetration testers. The testers reverse engineered a privileged executable. In the report, the planning and execution of the exploit is detailed using logs and outputs from the test However, the attack vector of the exploit is missing, making it harder to recommend remediation's. Given the following output:

The penetration testers MOST likely took advantage of:

  • A. A buffer overflow vulnerability
  • B. A TOC/TOU vulnerability
  • C. An integer overflow vulnerability
  • D. A plain-text password disclosure

Answer: B


NEW QUESTION # 52
A small bank is evaluating different methods to address and resolve the following requirements
" Must be able to store credit card data using the smallest amount of data possible
* Must be compliant with PCI DSS
* Must maintain confidentiality if one piece of the layer is compromised Which of the following is the best solution for the bank?

  • A. Scrubbing
  • B. Tokenization
  • C. Masking
  • D. Homomorphic encryption

Answer: B

Explanation:
Tokenization is the process of replacing sensitive data, like credit card numbers, with unique identification symbols (tokens) that retain all the essential information without compromising its security. This method is compliant with PCI DSS requirements as it ensures that actual credit card data is not stored or processed, thus minimizing the risk of data breaches. Tokenization also maintains confidentiality even if part of the data handling system is compromised, as the tokens do not hold any exploitable data.


NEW QUESTION # 53
An engineering team has deployed a new VPN service that requires client certificates to be used in order to successfully connect. On iOS devices, however, the following error occurs after importing the .p12 certificate file:
mbedTLS: ca certificate undefined
Which of the following is the root cause of this issue?

  • A. The iOS keychain imported only the client public and private keys.
  • B. OpenSSL is not configured to support PKCS#12 certificate files.
  • C. iOS devices have an empty root certificate chain by default.
  • D. The VPN client configuration is missing the CA private key.

Answer: A

Explanation:
The root cause of this issue is that the iOS keychain imported only the client public and private keys, but not the CA certificate. A PKCS#12 file (.p12 or .pfx) is a file format that contains a certificate and its private key, optionally protected by a password. A PKCS#12 file can also contain intermediate certificates or root certificates that are needed to verify the certificate chain. However, when importing a PKCS#12 file into the iOS keychain, only the certificate and its private key are imported, not the CA certificate. This means that the iOS device cannot verify the authenticity of the certificate, and displays the error message "mbedTLS: ca certificate undefined". To fix this issue, the CA certificate needs to be imported separately into the iOS keychain, either manually or using a configuration profile. Verified References:
https://developer.apple.com/documentation/devicemanagement/certificatepkcs12
https://support.apple.com/guide/deployment/distribute-certificates-depcdc9a6a3f/web
https://openvpn.net/faq/how-do-i-use-a-client-certificate-and-private-key-from-the-ios-keychain/


NEW QUESTION # 54
A security administrator needs to implement a security solution that will
* Limit the attack surface in case of an incident
* Improve access control for external and internal network security.
* Improve performance with less congestion on network traffic
Which of the following should the security administrator do?

  • A. Integrate threat intelligence feeds into the FIM
  • B. Update firewall rules to match new IP addresses in use
  • C. Deploy DLP rules based on updated Pll formatting
  • D. Configure SIEM dashboards to provide alerts and visualizations

Answer: B

Explanation:
Updating firewall rules to match new IP addresses in use will help to limit the attack surface in case of an incident by ensuring only legitimate traffic is allowed. It can also improve access control for external and internal network security by ensuring that only authorized entities can access certain resources, and may improve network performance by reducing unnecessary traffic (less congestion).


NEW QUESTION # 55
Which of the following is a benefit of using steganalysis techniques in forensic response?

  • A. Maintaining chain of custody for acquired evidence
  • B. Determining the frequency of unique attacks against DRM-protected media
  • C. Identifying least significant bit encoding of data in a .wav file
  • D. Breaking a symmetric cipher used in secure voice communications

Answer: C

Explanation:
Steganalysis is the process of detecting hidden data in files or media, such as images, audio, or video. One technique of steganalysis is to identify least significant bit encoding, which is a method of hiding data by altering the least significant bits of each byte in a file. For example, a .wav file could contain hidden data encoded in the least significant bits of each audio sample. Steganalysis techniques can help forensic responders to discover hidden evidence or malicious payloads. Breaking a symmetric cipher, determining the frequency of attacks, or maintaining chain of custody are not related to steganalysis. Verified Reference: https://www.comptia.org/blog/what-is-steganography https://partners.comptia.org/docs/default-source/resources/casp-content-guide


NEW QUESTION # 56
A creative services firm has a limited security budget and staff.
Due to its business model, the company sends and receives a high volume of files every day through the preferred method defined by its customers.
These include email, secure file transfers, and various cloud service providers.
Which of the following would BEST reduce the risk of malware infection while meeting the company's resource requirements and maintaining its current workflow?

  • A. Configure a network-based intrusion prevention system
  • B. Contract a cloud-based sandbox security service.
  • C. Enable customers to send and receive files via SFTP
  • D. Implement appropriate DLP systems with strict policies.

Answer: B


NEW QUESTION # 57
An organization is prioritizing efforts to remediate or mitigate risks identified during the latest assessment. For one of the risks, a full remediation was not possible, but the organization was able to successfully apply mitigations to reduce the likelihood of impact.
Which of the following should the organization perform NEXT?

  • A. Update the organization's threat model.
  • B. Recalculate the magnitude of impact.
  • C. Move to the next risk in the register.
  • D. Assess the residual risk.

Answer: D

Explanation:
Assessing residual risk involves specifying a treatment percentage to define how much of the treatment reduces the inherent risk.


NEW QUESTION # 58
A security architect is working with a new customer to find a vulnerability assessment solution that meets the following requirements:
- Fast scanning
- The least false positives possible
- Signature-based
- A low impact on servers when performing a scan
In addition, the customer has several screened subnets, VLANs, and branch offices. Which of the following will BEST meet the customer's needs?

  • A. Authenticated scanning
  • B. Passive scanning
  • C. Agent-based scanning
  • D. Unauthenticated scanning

Answer: D

Explanation:
Unauthenticated scanning is fast, has a lower impact on servers, and generates fewer false positives.


NEW QUESTION # 59
......

Best Value Available! Realistic Verified Free CAS-004 Exam Questions: https://www.lead2passexam.com/CompTIA/valid-CAS-004-exam-dumps.html

Pass Your Exam Easily! CAS-004 Real Question Answers Updated: https://drive.google.com/open?id=1VBxkmgFdC4WCGHUaAESboON398K1Cw45